logo

Google disrupts IPIDEA residential proxy networks fueled by malware

ID: b15d058e-82df-5196-9cba-5fab28607c8b

STIX ID: report--b15d058e-82df-5196-9cba-5fab28607c8b

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-01-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Google Threat Intelligence Group, with industry partners, disrupted IPIDEA — one of the largest residential proxy networks — which used trojanized Android apps (600+ apps embedding proxy SDKs) and thousands of trojanized Windows binaries to convert millions of consumer devices into proxy exit nodes. The network operated multiple consumer-facing brands tied to a centralized two-tier C2 infrastructure (roughly 7,400 servers), and was abused by hundreds of distinct threat groups for account takeover, credential theft, brute-force attacks, botnet control and record-setting DDoS operations; Google provided takedown actions and shared intelligence on the SDKs and infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.